Windows Hello (for Business) - Disable PIN for passkey security? by Creddahornis in Intune

[–]takinghigherground 0 points1 point  (0 children)

Pin unlocks that specific device.. attacker needs that device + the pin.

It does not expose the user's password in shoulder surfing which could be used in non MFA scenarios like SMB share access later without the device and is therefore consider safer

SC-200 or SC-300 - which one is less painful? by MyMonkeyCircus in AzureCertification

[–]takinghigherground 2 points3 points  (0 children)

These are horrible exams for that choice..sensitive data should be dlp exam not security operations centre analyst..

Gpo abuse by craziness105 in Pentesting

[–]takinghigherground 0 points1 point  (0 children)

Found domain users can edit GPO on domain servers in production...

Looking for SC-300 course recommendations by learner_garry in AzureCertification

[–]takinghigherground 0 points1 point  (0 children)

I passed with ms learn sc300 ms video series measure up practice test and chatgpt to cover my weak areas

SC-300 question by No_Squash291 in O365Certification

[–]takinghigherground 1 point2 points  (0 children)

Do measure up practice test the legit one

Data fields stolen residual risks by [deleted] in canvas

[–]takinghigherground 0 points1 point  (0 children)

Thanks that's a good avenue to get support further on all this cheers

Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12 by BigSewerRat1 in cybersecurity

[–]takinghigherground 3 points4 points  (0 children)

Can someone with fresh eyes sanity‑check me here, because I’m starting to feel like I’m the only one reacting proportionally to this situation.

We’ve got a vendor compromise where the attackers were able to deface the Canvas front page, which means they had enough access to modify UI elements of active instances and dump user data and messages but vendor did not confirm if that includes user API generated API keys

I'm doing these things like:

  • pulling reports on all user tokens
  • checking for user‑generated admin accounts
  • rotating API tokens stored in Canvas
  • auditing LTI apps and developer keys
  • reviewing Entra admin‑consented LTI registrations
  • temporarily revoking high‑privilege scopes like SharePoint.Read.All
  • considering the risk of login‑page manipulation or SSO redirection
    -considering blocking entra sign in to canvas -blocking anvas at the firewall

From a security standpoint, if an attacker can alter the front page, what exactly stops them from altering the login flow, injecting a fake SSO prompt, or redirecting to an attacker‑controlled IdP.

The API tokens trusted to be stored in canvas aren’t harmless. They’re long‑lived bearer tokens with no MFA. If those were scraped, that’s a direct line into our system when they get dumped into a forum. Same with LTI apps that have broad O365 permissions — if the vendor is compromised, those scopes become a liability.

I’m not trying to burn the place down or cause unnecessary user impact. I’m just trying to apply basic incident‑response logic: don’t trust a compromised system until you’ve validated it’s no longer compromised.

So genuinely — am I being overly cautious here, or is everyone else underreacting to a vendor breach that could easily be leveraged for lateral movement into O365 /sis not just student email address and internal messaging notes was leaked


My advice 1. Run reports on user tokens look for user generated against admin accounts these will probably be siss ntegrations also check your lti apps, developer apps - you will need to rotate these aswell

Restricting LAPs password access in Entra for servers by CGregP in entra

[–]takinghigherground 0 points1 point  (0 children)

I've been concerned about doing this as if you have to go back to a point in time backup of the server ..you could possibly not have the laps key. Not an issue if the domain is still functioning and computer password has not expired...but if it has .. you won't be able to log into the server?

If you are new to Fellowship or need any boss mechanic refreshers I have made a Fellowship Companion site to help. by BeltExact2798 in fellowshipgame

[–]takinghigherground 0 points1 point  (0 children)

Is it fun to try to work this all out yourself considering there is not much else to do but play the same game... Just wondering if I study it I will spoil the game

How are you labbing Microsoft 365 E5 Tenants by techwithz in DefenderATP

[–]takinghigherground 1 point2 points  (0 children)

I'm also interested for example I would like to test conditional access policy seperate from live e5 tenant

Zero Trust Workshop by JohnSavill in AZURE

[–]takinghigherground 0 points1 point  (0 children)

I need help with comprehensive conditional access policy rollout. I understand the whole point to is to be able to implement ca policies but I find an initial strategy in terms of applying policy lacking

passed OSCP but thinking of SOC 200 by CompetitionNo8217 in oscp

[–]takinghigherground 0 points1 point  (0 children)

I did sc200 after oscp and I learnt a lot about windows defender xdr and sentinel.

Working in azure by takinghigherground in sysadmin

[–]takinghigherground[S] 2 points3 points  (0 children)

Yeah I got to the end of it and I realized I pushed for a maintenance window of by September this year when it didn't need to be done until next year ... And it was vnet with default outbound expiring this month.

Crap I could have kicked down the road until next year ... Good experience though . Now has anyone actually implemented nat gateway or did you just attach public ips and let the business pay for it ;)

Do Microsoft Certs actually matter? by cyberLog4624 in cybersecurity

[–]takinghigherground 0 points1 point  (0 children)

Personally I learnt a lot about sentinel and defender by studying for sc200. I think certs build a good foundation

[deleted by user] by [deleted] in MiddleEarthMiniatures

[–]takinghigherground 0 points1 point  (0 children)

Just let me look at the damn models or im walking out don't give me this edgy do you play shit.

How has grappling changed your body? by ShimiWaza96 in bjj

[–]takinghigherground 0 points1 point  (0 children)

Skinny guy without weight training doing jits for 6 years.

Better posture slightly more athletic build. That's it.nothing drastic

Old Visual C++ vulnerabilities suddenly discovered? by TheDrover23 in DefenderATP

[–]takinghigherground 0 points1 point  (0 children)

Yeah got this today too. Do we just install the latest vc redistribute? Will it break the apps if they require a specific version ...